Trusted Device Passports: How Data Spaces Enable Sovereign IMEI Sharing for Homologation
September 20, 2026
Counterfeit handsets pass network checks by carrying an IMEI harvested from an approved device, so regulators ask manufacturers for ever larger identity datasets. Manufacturers resist, because those datasets reveal production volumes, market allocations and launch plans. This whitepaper, prepared by Apkudo with the GSMA and the International Data Spaces Association, describes the architecture behind the GSMA Device Homologation Pilot Program: the regulator's question reaches the manufacturer's own systems and returns a single approval status. It also answers what OEMs ask before joining anything, including where their data sits, who runs the software that answers queries, what the shared rulebook governs and what happens during one verification.
What blocks global homologation is trust between regulators and manufacturers, not missing technology.
A bulk IMEI file gives away far more than device identity: manufacturing yield, volumes shipped to each market and launch sequencing can all be inferred from it.
In a data space the data stays where it already lives. The query is checked against the manufacturer's own policies, runs locally and returns one answer.
The Device Passport is deliberately narrow. It carries the queried IMEI, the model behind its TAC, the manufacturer's verified identity, an approval status for the market in question and, where the rules require one, a validity date.
Building this infrastructure for homologation also prepares manufacturers for the Digital Product Passport that the EU Ecodesign for Sustainable Products Regulation will require for consumer electronics by 2030.
What's Inside the Whitepaper
The cost of counterfeit devices: How IMEI cloning lets substandard hardware clear network checks, and what quarantined shipments and homologation delays cost a manufacturer during a launch window.
Why bulk sharing keeps failing: What a central IMEI repository exposes, why uploading to one ends the manufacturer's control over later use, and why every participant shares the risk of a single breach.
What a data space actually is: Sharing answers instead of copies, with usage rules enforced by software rather than by contract, and no central store to attack.
Where the data lives: Why joining means no upload and no migration, what the connector does before and after a query is approved, and the choice between running it yourself and having Apkudo run it under your rules.
The Device Passport and one query, step by step: The fields a query can reach, the commercial data the model cannot express, and the path from a regulator's request to a single status answer.
Governance and next steps: The rulebook every participant signs up to, the GSMA's role as scheme owner and keeper of the audit log, and what OEMs and regulators do to join the pilot.
By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.